Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 23 additions & 0 deletions content/docs/analyzers/ApplicationCop/AC0031.md
Original file line number Diff line number Diff line change
Expand Up @@ -165,6 +165,29 @@ procedure ReadCustomer()

**Page `SourceTable` exemption** covers all CRUD on the page's own source table, including in page extensions. A page that sets `SourceTable = Customer` does not need to declare permissions for `Customer`.

**Object-level `AccessByPermission` property** on a report or page covers the permissions in its mask for the table it names. The property hides the object from users who lack those permissions, so an object that declares it is meant for users who already hold them and does not rely on indirect access through the object:

```al
report 50100 "Process Incoming Documents"
{
ApplicationArea = All;
UsageCategory = Tasks;
ProcessingOnly = true;
AccessByPermission = tabledata "Incoming Document" = RM;

dataset
{
dataitem(IncomingDocument; "Incoming Document") // No diagnostic: R is in the mask
{
}
}
}
```

Only the permissions in the mask count, regardless of casing: with `= RD`, reads and deletes on the table are covered but a `Modify` still reports a missing `m`. The `table X = X` form (permission to run an object) and entries for other tables cover nothing. `AccessByPermission` on individual fields, actions and parts is not considered.

`AccessByPermission` does not grant permissions at runtime. The check passes when the user has at least one of the permissions in the mask, it only applies when the server's UI elements removal setting is `LicenseFile` or `LicenseFileAndUserPermissions`, and the object can still be run from code or from an action with `RunObject`. Add the `Permissions` property when the object must work for users who have only indirect permissions on the table.

Namespace-qualified references (`tabledata MyNamespace."My Table" = r`) and object ID references (`tabledata 50100 = r`) are both recognized.

### Temporary tables
Expand Down
Loading